Malicious PDF — malware analysis report

Static analysis result for SHA-256 74c69940f96ccad2…

MALICIOUS

PDF

74.4 KB Created: 2024-01-03 00:00:00 Authoring application: LibrarySystem_34 (via Producer_17)
MD5: 3a0baa797d0f1c7fb1d4eb267debe554 SHA-1: 4d74de5d8a269eb22bdc2ab3563d7fd4f819d1a9 SHA-256: 74c69940f96ccad21c7bfa75d6ee8dec4a78b16e0a32abe104d24c2076a574d5
84 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF is identified as an image-only lure, typical of phishing attacks designed to trick users into clicking a link. The embedded link directly points to a payload, indicating an attempt to deliver malware. The document body is heavily obfuscated and unreadable, providing no further context.

Machine Learning

  • Nyx PDF Classifier clean score 0.0033

Heuristics 4

  • PDF link points directly to executable/archive payload critical PDF_DIRECT_PAYLOAD_LINK
    PDF contains a clickable HTTP(S) URI whose path ends in an executable, script, shortcut, disk image, or archive extension. Documents can legitimately link to installers, so this is a high-risk delivery indicator rather than a standalone exploit fingerprint.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 2 image(s), only 0 text block(s), carries a click-outward action, and is only 74 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://adclick.g.doubleclick.net//pcs/click?f1587wub8-24-TzRtAOnedriveBskd&&adurl=//selectwendormo9tres.com?utm_content=AAhqplxaJo&session_id=3VHLBRuVfwDKTPWgylgR&id=b2WBu&filter=FSBMsIgzmQ-pIvZl&lang=zh&locale=US

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000da52.bin
df81849862a3ba199bae1dffeee44aa39273d6c2c1d19d8550396604c8ec5c73
pdf-font-stream PDF embedded font (sfnt) at offset 0xDA52 5980 bytes
font_01_sfnt_off0000edb4.bin
fcb5a74c7a9810c20dda22eccb67f73b069160eced8adcd7ee2e67464c96075c
pdf-font-stream PDF embedded font (sfnt) at offset 0xEDB4 2407 bytes
font_02_sfnt_off0000f8b9.bin
b3a607e4bf030e1c90b076d5f41e8dd93acbc6d87ac92987b19c8f825a9af62a
pdf-font-stream PDF embedded font (sfnt) at offset 0xF8B9 6001 bytes
font_03_sfnt_off00010e79.bin
566618c4f33bb8cbf2331433175e253fedf1f79597e417124e5be3c2564a85e0
pdf-font-stream PDF embedded font (sfnt) at offset 0x10E79 7300 bytes